Balance — India Country Annex
Effective date: 19 July 2026 Last updated: 19 July 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Indian resident covered by this Annex; the contact person discharging the Data Fiduciary contact-publication duty under the Digital Personal Data Protection Act, 2023 (the "DPDP Act") Section 5(1)(iii) read with the Digital Personal Data Protection Rules, 2025 (notified 14 November 2025, the "DPDP Rules 2025") — the business contact for the purposes of answering questions about the processing of personal data is ; the designated contact point for the Data Protection Board of India (the "Board"), the Ministry of Electronics and Information Technology ("MeitY"), the Indian Computer Emergency Response Team ("CERT-In"), the National Crime Records Bureau / National Cyber Crime Reporting Portal, and the Central Consumer Protection Authority ("CCPA"), under their respective intake protocols.
Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023, assented 11 August 2023) or any change in the phased commencement of its provisions; (b) any amendment to the DPDP Rules 2025 (notified 14 November 2025 with phased commencement — verify the rules in force at each review) or any further rules, notifications, or standards issued under DPDP Act Section 40; (c) any notification by the Central Government under DPDP Act Section 16 restricting transfer of personal data to any country or territory outside India (none notified at the Effective date); (d) any exemption notification under DPDP Act Section 9(5) or any change to the Fourth Schedule of the DPDP Rules 2025 (Part B "safety of the child" purposes); (e) any designation of Balance as a Significant Data Fiduciary under DPDP Act Section 10 (not designated at the Effective date); (f) any amendment to the Information Technology Act, 2000 ("IT Act") — in particular Section 67B (child sexual abuse material) — or to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 ("IT Rules 2021"); (g) any amendment to the Protection of Children from Sexual Offences Act, 2012 ("POCSO") — in particular the Section 19 mandatory-reporting duty and Sections 13-15 (child pornography offences); (h) any amendment to the Consumer Protection Act, 2019 ("CPA 2019") or the Consumer Protection (E-Commerce) Rules, 2020; (i) any decision of the Supreme Court of India or a High Court bearing on the DPDP Act or on the constitutional right to privacy under Justice K.S. Puttaswamy (Retd.) v Union of India (2017) 10 SCC 1 (Article 21); (j) any amendment to the Bharatiya Nyaya Sanhita, 2023 insofar as it engages child-protection or obscenity offences; (k) any change to a sub-processor's India data-handling posture under our sub-processor register; (l) the bringing into force of any post-Effective-date Indian regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex); (m) any CERT-In direction (including the CERT-In Directions of 28 April 2022 on incident reporting) that materially alters the operational rules below.
Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — India row).
- Children's Privacy Notice § 14 (Country annexes — India row).
- Child Safety Standards § 13 (Country annexes — India row).
- Terms of Service § 17 (India consumer-protection carve-out under the Consumer Protection Act, 2019 + the Consumer Protection (E-Commerce) Rules, 2020).
- Subscription Terms § 18 (India consumer-rights overlay — refund and disclosure rules under the CPA 2019 + E-Commerce Rules 2020).
- Data Retention & Deletion Policy § 13 (India — Data Protection Board complaint route).
- our breach-notification runbook § 9 (India personal-data-breach notification route under DPDP Act Section 8(6) + the DPDP Rules 2025 + the CERT-In Directions 2022).
- our international-transfer pack § 6 (DPDP Act Section 16 cross-border-transfer position).
This Annex is the canonical Indian-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants an Indian resident a right that the global Policy does not, this Annex governs. Where the global Policy grants an Indian resident a right that this Annex does not, the global Policy governs. The two are read together.
This Annex is drafted in English. English is one of the two official languages of the Union under the Constitution of India Article 343 read with the Official Languages Act, 1963, and is an accepted language for the DPDP Act Section 5 notice. DPDP Act Section 5(3) gives the Data Principal the option to access the notice in English or any of the twenty-two languages specified in the Eighth Schedule to the Constitution of India; Balance provides the notice in English and will provide an Eighth-Schedule-language rendering of the Section 5 notice on request at (per the locked product decision, the published documentation set for India is English-only at the Effective date).
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is India — the Union of India comprising 28 States and 8 Union Territories. The DPDP Act is a Union statute enacted under the Seventh Schedule; there is no State-level data-protection sub-layer that derogates from the DPDP Act in respect of Balance's processing.
We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region. Where any of the three signals identifies India, this Annex applies; the most-protective-for-the-data-subject reading controls per our internal compliance plan § 6.3.
The DPDP Act has explicit territorial reach defined at Section 3(b): the Act applies to processing of digital personal data outside the territory of India if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India. Balance offers its service to Indian residents through Google Play India and through publication of this Annex; the DPDP Act applies in respect of all personal data Balance processes in connection with Indian-resident users via the Section 3(b) offer-of-services limb. Balance is the Data Fiduciary; the parent and the kid are Data Principals; under DPDP Act Section 2(j), in respect of a child, "Data Principal" includes the parents or lawful guardian of such a child — the parent therefore exercises the kid's rights.
2. Statutory framework — what applies
The Indian personal-data-protection regime is dominated by the Digital Personal Data Protection Act, 2023, operationalised by the DPDP Rules 2025 (notified 14 November 2025 with phased commencement — the institutional provisions and the Board-establishment rules commenced first; the substantive Data-Fiduciary obligations commence per the notified schedule; Balance applies the full substantive regime voluntarily from the Effective date without waiting for the final commencement dates). Adjacent layers: the constitutional right to privacy (Article 21, Puttaswamy); the IT Act 2000; the IT Rules 2021; POCSO 2012; the CPA 2019 + E-Commerce Rules 2020; the Bharatiya Nyaya Sanhita, 2023; the CERT-In Directions 2022.
| Instrument | What it does | Balance's posture |
|---|---|---|
| Constitution of India — Article 21 read with Justice K.S. Puttaswamy (Retd.) v Union of India (2017) 10 SCC 1 | The fundamental right to privacy — informational privacy recognised as intrinsic to the right to life and personal liberty. | The constitutional anchor. Treatment in §§ 3, 6, 13 below. |
| Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) | The principal statute. Section 3(b) extraterritorial reach; Section 4 lawful processing only for a lawful purpose with consent (Section 6 — free, specific, informed, unconditional, unambiguous, clear affirmative action) or for certain legitimate uses (Section 7); Section 5 notice duty; Section 8 general obligations of the Data Fiduciary including 8(5) security safeguards and 8(6) breach intimation; Section 9 processing of personal data of children (under 18) — 9(1) verifiable parental consent before processing; 9(2) no processing likely to cause detrimental effect on the well-being of a child; 9(3) prohibition of tracking or behavioural monitoring of children or targeted advertising directed at children; 9(5) exemption power (operationalised by the DPDP Rules 2025 Fourth Schedule — Part B exempts specified purposes including processing "in the interests of safety of the child" from the 9(1)/9(3) restrictions to the extent necessary); Sections 11-14 Data-Principal rights (access, correction and erasure, grievance redressal, nomination); Section 16 cross-border transfers (permitted to every country not restricted by Central-Government notification — none restricted at the Effective date); Section 10 Significant Data Fiduciary tier (Balance not designated); Sections 18-28 the Data Protection Board of India; Section 33 + Schedule monetary penalties (up to INR 250 crore for failure of security safeguards; up to INR 200 crore for breach of children's-data obligations). | The principal statute. Applies in full via Section 3(b). Treatment in §§ 3-8, 11 below. |
| DPDP Rules 2025 (notified 14 November 2025) | Operationalises the DPDP Act: the form and manner of the Section 5 notice; the mechanics of verifiable parental consent (identity-and-age verification of the person identifying as the parent, using reliable details or a virtual token); the Fourth Schedule exemptions (Part B — purposes for which the Section 9(1) consent and Section 9(3) tracking/behavioural-monitoring restrictions do not apply to the extent necessary, including the safety of the child); breach-intimation form and timelines; retention-and-erasure mechanics; Consent-Manager registration (Balance does not act as a Consent Manager); Board procedure. | Applies. Balance implements the verifiable-parental-consent mechanics at § 5 + § 7 below. |
| Information Technology Act, 2000 | Section 67B — publishing / transmitting / browsing material depicting children in sexually explicit acts (imprisonment up to 5 years + fine on first conviction); Section 79 intermediary safe harbour (Balance does not rely on it — Balance is a closed family system, not a public intermediary surface); Section 69 lawful-interception powers with procedural safeguards. | Applies. Treatment in §§ 13, 14 below. |
| IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 | Due-diligence and grievance duties for intermediaries and publishers. Balance's parental-control service is a closed family system without a public content-hosting or content-discovery surface; the intermediary-specific duties are not engaged on the ordinary reading — Balance nonetheless honours the child-safety substance voluntarily. § 18 versioning protocol covers any classification change. | Applies as a context-setting fact. |
| Protection of Children from Sexual Offences Act, 2012 (POCSO) | The principal child-sexual-offences statute — Sections 13-15 (use of child for pornographic purposes; storage of child pornography), Section 19 mandatory reporting: any person who has apprehension or knowledge that an offence under POCSO is likely to be or has been committed shall report to the Special Juvenile Police Unit or the local police; Section 21 penalty for failure to report. | Applies — the Section 19 duty binds Balance personnel. Treatment in § 14 below. |
| Consumer Protection Act, 2019 + Consumer Protection (E-Commerce) Rules, 2020 | Consumer rights (Section 2(9)), unfair trade practices, product/service liability, the Central Consumer Protection Authority (CCPA), District/State/National Consumer Disputes Redressal Commissions; the E-Commerce Rules impose transparency, grievance-officer response timelines, and refund duties on e-commerce entities. | Applies. Treatment in § 16 below. |
| CERT-In Directions of 28 April 2022 (under IT Act Section 70B(6)) | Cyber-incident reporting to CERT-In within 6 hours of noticing specified categories of incidents; log-retention expectations. | Applies to the extent Balance's incidents fall within the specified categories. Treatment in § 11 below. |
| EU adequacy | None. India does not hold an EU adequacy decision under GDPR Article 45 at the Effective date. | Context-setting fact; Balance has no India data residency (backend in the US — § 9 below). |
| Convention 108 / Budapest Convention | India is not a party to Convention 108/108+ and has not acceded to the Budapest Convention. Cross-border lawful access runs via MLATs and letters rogatory (CrPC/BNSS provisions). | Context-setting fact. Treatment in § 13 below. |
(Any prospective Indian regulation governing automated processing, algorithmic decisions, or related techniques — including MeitY's advisories on AI systems, the National Strategy for Artificial Intelligence, any future Digital India Act, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)
3. Supervisory authorities
3.1 Data Protection Board of India
The principal enforcement body is the Data Protection Board of India (the "Board"), established under DPDP Act Sections 18-28 as a digital-by-design adjudicatory body: it receives personal-data-breach intimations, inquires into breaches of the Act on complaint or reference, and imposes the Section 33 monetary penalties. Appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) (Section 29).
| Field | Value |
|---|---|
| Name | Data Protection Board of India |
| Parent ministry | Ministry of Electronics and Information Technology (MeitY) |
| Website / complaint channel | The Board's digital-office portal as notified under the DPDP Rules 2025 (published via https://www.meity.gov.in/) |
| Appeal | Telecom Disputes Settlement and Appellate Tribunal (TDSAT), New Delhi — https://tdsat.gov.in/ |
An Indian resident may complain to the Board after exhausting the grievance-redressal opportunity with Balance (DPDP Act Section 13(3): the Data Principal shall first exhaust the grievance channel before approaching the Board). We accept all grievances and data-principal enquiries at (named individual: ) and respond within the timelines in § 6 below.
3.2 Other regulatory bodies
| Body | Subject matter | URL / channel |
|---|---|---|
| Ministry of Electronics and Information Technology (MeitY) | DPDP Act administration; IT Act; IT Rules 2021 | https://www.meity.gov.in/ |
| CERT-In | Cyber-incident reporting (IT Act Section 70B) | https://www.cert-in.org.in/ — incident@cert-in.org.in |
| Central Consumer Protection Authority (CCPA) + Consumer Commissions | CPA 2019 + E-Commerce Rules 2020 | https://consumerhelpline.gov.in/ — National Consumer Helpline 1915 |
| National Cyber Crime Reporting Portal (Ministry of Home Affairs) | Cybercrime including online CSAE — dedicated CSAM reporting track | https://cybercrime.gov.in/ — Helpline 1930 |
| Special Juvenile Police Unit / local police | POCSO Section 19 mandatory reports | Dial 112 (emergency); local SJPU |
| National Commission for Protection of Child Rights (NCPCR) | Child-rights complaints | https://ncpcr.gov.in/ |
| Childline 1098 | 24/7 children's helpline | dial 1098 (toll-free within India) |
3.3 The contact person
The DPDP Act does not impose a general DPO mandate on non-Significant Data Fiduciaries; Section 5(1)(iii) + the DPDP Rules 2025 require publication of the business contact of a person able to answer questions about the processing. That person is , Director, BabaYaga Program, TOO — , published in this Annex, in the global Privacy Policy § 1, and at balance.babayagaprogram.com. If Balance is ever designated a Significant Data Fiduciary (Section 10), a Data Protection Officer based in India would be required; that designation has not occurred at the Effective date and the exposure is tracked internally (§ 18 versioning protocol).
4. Lawful bases — DPDP Act Section 4 (consent) + Section 7 (legitimate uses)
The DPDP Act is a consent-first regime. Balance's mapping:
- Parent account data (identity, authentication, subscription state): consent under Section 6 obtained at sign-up via the consent screen (free, specific, informed, unconditional, unambiguous, clear affirmative action), plus Section 7(a) voluntary-provision legitimate use for data the parent volunteers for the specified purpose.
- Kid profile + device data (usage totals, app-limit state, tasks, earned-time ledger, device identifiers, push tokens): verifiable parental consent under Section 9(1) obtained per § 5 below.
- Monitoring / limits / tasks functionality: performed at the parent's direction, strictly for the safety, well-being and parental supervision of the child — within the DPDP Rules 2025 Fourth Schedule Part B "safety of the child" purpose to the extent the Section 9(3) restrictions would otherwise bite (§ 5 below).
- Security, fraud-prevention, legal-compliance processing: Section 7 legitimate uses (compliance with law / judgment / order — Section 7(c)), plus the parent's consent umbrella.
- No processing for advertising, profiling, or sale. Balance processes no personal data for targeted advertising and engages no Section 9(3)-prohibited purpose. Withdrawal of consent is honoured at any time (Section 6(4)-(6)) with the ease-of-withdrawal parity the Act requires; withdrawal cascades per Data Retention & Deletion Policy § 7.
5. Children's rights overlay — Section 9 + the Fourth Schedule Part B anchor
Under the DPDP Act a child is a person under 18. Balance's India posture, stated plainly:
- The parent always consents; the kid never self-registers. A kid profile can only be created inside an authenticated parent account; the kid's device is paired by the parent's affirmative act. This is the Section 9(1) verifiable parental consent by design: the consenting adult is the account holder whose identity is verified through the email-verified account creation, the Google Play payment instrument where a subscription is purchased, and the DPDP-Rules-2025-conformant consent flow that itemises categories, purposes, recipients and rights. Balance observes due diligence that the person giving consent identifies as the parent or lawful guardian per the DPDP Rules 2025 verifiable-consent mechanics.
- The Fourth Schedule Part B anchor. Balance's monitoring, screen-time limits, app limits and task features are performed at the parent's direction, strictly for the safety, well-being and parental supervision of the child, and are never used for advertising, profiling, or any commercial purpose. To the extent any feature constitutes "tracking or behavioural monitoring" within Section 9(3), it is undertaken in the interests of safety of the child within the DPDP Rules 2025 Fourth Schedule Part B, restricted to the extent necessary for that purpose — which is exactly how the product is built (deterministic usage totals and limits, visible to the parent; no advertising surface; no profiling engine; no data sale).
- Section 9(2) — no processing likely to cause detrimental effect on the well-being of the child: Balance's DPIA (our Data Protection Impact Assessment) records the well-being analysis; the product surfaces no content feed, no social graph, no contact-by-strangers surface.
- Section 9(3) triple lock embraced. No tracking or behavioural monitoring for our purposes, no targeted advertising directed at children — a statutory command Balance embraces as product policy in every country (cross-reference Children's Privacy Notice § 6).
- Rights exercise: under Section 2(j) the parent exercises the kid's Data-Principal rights; the grievance channel in § 6 below is open to the parent on the kid's behalf and to the kid (age-appropriately) via the parent.
6. DPDP Act rights catalogue
An Indian resident has the following rights under DPDP Act Sections 11-14:
- Section 11 — Right to access information about personal data: a summary of the personal data being processed, the processing activities, the identities of all Data Fiduciaries and Data Processors with whom the data has been shared, and the categories shared. Honored at
and in-app at Settings → Family → [kid name] → "Export this kid's data" (machine-readable JSON + plain-language summary); the canonical share-list is § 10 of this Annex + our sub-processor register. - Section 12 — Right to correction and erasure: correction of inaccurate/misleading data, completion, updating, and erasure of personal data no longer necessary (unless retention is required by law). Honored in-app at Settings → Account → Edit; Settings → "Delete my account" / "Delete this kid"; Delete-account page; or
. Cascade per Data Retention & Deletion Policy § 7. - Section 13 — Right of grievance redressal: a readily-available means of grievance redressal, which the Data Principal must exhaust before approaching the Board. Balance's grievance officer contact is
(named individual: ). Timeline: we acknowledge within one business day and resolve within the period prescribed by the DPDP Rules 2025 for our class of Data Fiduciary — and in any event within 30 days, which is Balance's self-imposed ceiling. - Section 14 — Right to nominate: the Data Principal may nominate another individual to exercise these rights in the event of death or incapacity. Honored at
— the nomination is recorded against the parent account. - Duties (Section 15): the Act also imposes duties on Data Principals (no impersonation, no false particulars, no frivolous complaints) — noted for completeness.
Requests may be submitted in English or in any Eighth-Schedule language (we will translate on receipt). Identity verification uses the parent's existing authentication credential; out-of-band verification is a last resort. The exercise of rights is free of charge.
7. Children's data — verifiable parental consent mechanics
The DPDP Rules 2025 require the Data Fiduciary to ensure verifiable consent of the parent before processing a child's personal data, adopting appropriate technical and organisational measures to check that the individual identifying as the parent is an adult who is identifiable if required. Balance's mechanism:
- Parent creates the account with a verified email; where a subscription is purchased, the Google Play payment instrument corroborates adulthood; the parent then performs the affirmative in-app act of creating the kid profile and pairing the kid's device.
- The consent screen itemises the categories of the kid's data processed, the purposes (safety, well-being and parental supervision only), the sub-processors, the retention rules, and the Sections 11-14 rights — satisfying the Section 5 notice duty in respect of the child's data.
- The kid cannot self-register, cannot un-pair without the parent, and has no surface through which the kid's data leaves the family system.
- Proof media (photos the kid submits as task evidence) is end-to-end encrypted on the kid's device to the parent's device keys; Balance holds ciphertext only (§ 13 below).
8. International data transfers from India — DPDP Act Section 16
DPDP Act Section 16 permits transfer of personal data outside India to every country except a country restricted by Central-Government notification. No country has been restricted at the Effective date — transfers from India to the United States (hosting) and Kazakhstan (controller access) are therefore lawful under Section 16 without a further transfer instrument. Balance nonetheless:
- discloses the transfers plainly at sign-up (the transfer-disclosure consent in the global Privacy Policy § 7 names the US hosting and the controller's Kazakhstan seat);
- binds every sub-processor by written data-processing agreements with security and confidentiality controls (§ 10 below);
- applies the E2EE supplementary measure to proof media (ciphertext-only US storage);
- monitors Section 16 notifications and any sectoral localisation mandate (none applies to Balance's processing at the Effective date; RBI payment-data localisation does not engage Balance because payments are processed by Google Play Billing). § 18 versioning protocol covers any change.
9. Data residency for Indian residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region (E2EE ciphertext only). |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Indian resident's data held in India? | No. Every Indian resident's data is held in the United States. DPDP Act Section 16 permits the transfer (§ 8 above). |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO), with administrative access to the US-hosted backend under written processor DPAs. |
| Is there an Indian establishment? | No. Balance has no permanent establishment in India. |
India does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date.
10. Sub-processors touching Indian-resident data
| Sub-processor | Role | Location | India transfer basis |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS + Privacy Policy (full handling in our internal vendor-handling plan) | Hosts the FastAPI backend + MongoDB cluster | United States | DPDP Act Section 16 (no restricted-country notification); DPA + security controls on file per our international-transfer pack § 6; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | Stores E2EE proof-media ciphertext + daily 30-day-rolling database backups | United States (us multi-region) |
Section 16; Google Cloud Data Processing Addendum; ciphertext-only handling of proof media. |
| Google LLC — Firebase Cloud Messaging | Delivers push notifications to Indian kid + parent devices | United States | Section 16; push body deliberately free of sensitive content (the just-in-time permission disclosures). |
| Google LLC — Google Sign-In | Authenticates parent Google identity (when used) | United States | Section 16; Google DPA. |
| Google LLC — Google Play Billing | Processes subscription purchases | United States / India (Google Play India) | Section 16; Google Play Developer Distribution Agreement. |
| Resend, Inc. (San Francisco, CA, USA) | Delivers transactional email to Indian parent users | United States | Section 16; DPA on file. |
Every sub-processor is bound by a written data-processing agreement that forbids processing for any purpose other than performing the engaged service. The full list with DPA status is at our sub-processor register.
11. Breach notification — DPDP Act Section 8(6) + DPDP Rules 2025 + CERT-In Directions 2022
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| Affected Data Principals | Any personal data breach (DPDP Act Section 2(u): any unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability). | Without delay, in the form and manner of the DPDP Rules 2025 — plain-language description, consequences, mitigation, safety measures the individual may take, and our contact. | Direct email to the affected parent; in-app banner; public incident page if email is undeliverable. |
| Data Protection Board of India | The same breach. | Per the DPDP Rules 2025 two-stage intimation: prompt initial intimation, followed by the detailed report within 72 hours (extendable on request). | The Board's digital portal, filed by the Privacy Officer. |
| CERT-In | Incidents within the categories specified by the CERT-In Directions 2022. | Within 6 hours of noticing. | incident@cert-in.org.in / CERT-In portal. |
| CSAE-specific | An incident with a CSAE component. | Per § 14 below + the internal runbook (M1). | POCSO Section 19 route (SJPU/local police) + https://cybercrime.gov.in/ + (where applicable) NCMEC. |
The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9. Note the DPDP Act notification duty is not harm-thresholded — every personal data breach is notifiable to the affected Data Principals and the Board.
12. Cookies, spam, and electronic direct marketing
India has no standalone cookies statute; consent-based processing under the DPDP Act covers cookie-equivalent storage. The Balance app deploys strictly-necessary storage only (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache), covered by the sign-up consent. The public legal-documents site (balance.babayagaprogram.com) uses no analytics, no advertising cookies, no third-party trackers, no fingerprinting. Balance does not send electronic direct marketing to Indian residents — the only email is transactional (account creation, password reset, subscription receipts, security alerts, parent-action notifications). DPDP Act Section 9(3)'s ban on targeted advertising directed at children is honoured absolutely. The TRAI Telecom Commercial Communications Customer Preference Regulations, 2018 (unsolicited commercial communication) are not engaged because Balance sends no commercial SMS/voice communication.
13. Lawful-access requests and the encryption posture
Indian authorities may serve lawful-access requests via IT Act Section 69 / 69A / 69B orders (with their procedural safeguards), orders of a court, CrPC/BNSS production summonses, or MLAT/letters-rogatory channels (India is not a Budapest Convention party). The Balance architectural posture:
- Proof media is end-to-end encrypted. The kid's device generates a fresh per-file encryption key, encrypts the proof file with XChaCha20-Poly1305, wraps the key to each authorised parent device's X25519 public key, and uploads ciphertext + recipient-wrap envelopes only. We retain no master key and no means to decrypt.
- Response protocol: (1) acknowledge within one business day; (2) engage Indian counsel to assess validity; (3) preserve relevant ciphertext for the required period (subject to retention rules); (4) inform the authority that plaintext is not available from us; (5) cooperate in identifying the lawful route to the parent, who holds the decryption key.
- No bulk plaintext interception assistance; no server-side content scanning — there is no plaintext on our side to scan.
- CSAE-cooperation overlay: notwithstanding the encryption posture, Balance cooperates fully with Indian law enforcement on any CSAE referral via § 14, and Balance personnel discharge the POCSO Section 19 mandatory-reporting duty.
Full encryption posture: our encryption-posture record.
14. CSAE reporting routes — India
An Indian resident (parent, kid, or third party) may report a CSAE concern via:
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day. - POCSO Section 19 route: the Special Juvenile Police Unit or the local police — dial 112. Mandatory for any person with knowledge or apprehension of a POCSO offence.
- National Cyber Crime Reporting Portal:
https://cybercrime.gov.in/(dedicated women/children track; anonymous CSAM reporting supported) — Helpline 1930. - Childline 1098 — 24/7 toll-free children's helpline.
- NCPCR:
https://ncpcr.gov.in/(POCSO e-Box). - NCMEC CyberTipline (
https://report.cybertip.org/) — Balance's US-hosting nexus routes provider-side CSAM discoveries to NCMEC, which relays to Indian law enforcement via its international programme.
The full CSAE Country Routing Table is in Child Safety Standards § 8.5.
15. Complaint routes (summary)
| Authority | Subject matter | Channel |
|---|---|---|
| Data Protection Board of India | DPDP Act breaches (after exhausting our grievance channel — Section 13(3)) | Board digital portal via https://www.meity.gov.in/; appeal to TDSAT |
| CCPA / Consumer Commissions | CPA 2019 + E-Commerce Rules 2020 | https://consumerhelpline.gov.in/ — Helpline 1915 |
| National Cyber Crime Reporting Portal | Cybercrime + online CSAE | https://cybercrime.gov.in/ — 1930 |
| NCPCR | Child-rights complaints | https://ncpcr.gov.in/ |
| Courts | Constitutional (Art 32/226) + civil + criminal routes | Per jurisdiction |
An Indian resident should first raise the matter with us at (Section 13(3) exhaustion); we acknowledge within one business day and resolve within 30 days at the outside.
16. Consumer rights — the CPA 2019 + E-Commerce Rules 2020 overlay
- Pre-contract information: the E-Commerce Rules 2020 require clear disclosure of the total price, breakup charges, expiry, and refund terms — implemented in Subscription Terms § 5.
- Refunds: refund requests are honoured through the Google Play Billing refund route within the timelines of the E-Commerce Rules 2020; Balance's voluntary refund posture (Subscription Terms § 8) operates as the floor.
- Grievance officer: the E-Commerce Rules require a grievance officer who acknowledges within 48 hours and redresses within one month — Balance's grievance channel (
; escalation) meets both timelines. - Unfair trade practices / unfair contract terms: CPA 2019 Sections 2(46)-(47) — the Terms of Service are drafted to avoid each listed unfair term; consumer-forum jurisdiction (District/State/National Commissions, including where the complainant resides — CPA 2019 Section 34(2)(d)) is preserved (Terms of Service § 17-18).
- Contracting capacity: the age of majority is 18 (Indian Majority Act, 1875); the subscribing parent must be an adult; a minor's agreement is void under Mohori Bibee v Dharmodas Ghose (1903) — the kid never contracts with Balance.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — DPDP Act Section 16 position on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the bundle:
- Every change to a substantive row in §§ 2-16 bumps the frontmatter and triggers re-publication at Privacy Policy and
/children. - A change in the phased commencement of the DPDP Act / DPDP Rules 2025, a Section 16 restricted-country notification, a Fourth-Schedule amendment, or a Significant-Data-Fiduciary designation triggers an off-cycle rewrite of the affected sections (§§ 2, 5, 7, 8).
- A material amendment to POCSO / IT Act Section 67B triggers an off-cycle update to §§ 13-14.
- A material amendment to the CPA 2019 / E-Commerce Rules 2020 triggers an off-cycle update to § 16 + Subscription Terms.
- A material change to a sub-processor's posture triggers an off-cycle update to §§ 8, 10 + our sub-processor register.
- The annual review is by 9 June. The Privacy Officer signs the review off; the Designated Child Safety Officer co-signs any change to §§ 5, 7, 11, 13, 14.
End of India Country Annex.